Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015 Ran by Mike (administrator) on XXX on 26-06-2015 14:19:07 Running from C:\Users\Mike\Desktop Loaded Profiles: Mike & (Available Profiles: Mike) Platform: Windows 8.1 (X64) OS Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Microsoft Corporation) C:\Windows\vVX3000.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe () C:\Users\Mike\AppData\Local\Amazon Music\Amazon Music Helper.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Vimicro) C:\Program Files (x86)\USB Camera2\VM332STI.EXE (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe (Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe () C:\Program Files (x86)\DFX\DFX.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe () C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp32.exe () C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp64.exe () C:\Program Files (x86)\DFX\Universal\Apps\dfxItunesSong.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\ielowutil.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12921488 2012-07-02] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212560 2012-06-13] (Realtek Semiconductor) HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [366720 2012-06-26] (Alcor Micro Corp.) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17079376 2013-03-07] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191568 2013-03-07] (Lenovo(beijing) Limited) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-16] (Synaptics Incorporated) HKLM\...\Run: [VX3000] => C:\WINDOWS\vVX3000.exe [762736 2010-05-20] (Microsoft Corporation) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332STI.EXE [548864 2012-03-20] (Vimicro) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-19] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-11] (Avast Software s.r.o.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3727824 2015-06-16] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [DFX] => C:\Program Files (x86)\DFX\DFX.exe [1131880 2014-11-21] () HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [119152 2010-05-20] (Microsoft Corporation) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-1920574516-490169793-428975704-1001\...\Run: [BitTorrent] => C:\Users\Mike\AppData\Roaming\BitTorrent\BitTorrent.exe [1696104 2015-05-11] (BitTorrent Inc.) HKU\S-1-5-21-1920574516-490169793-428975704-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1920574516-490169793-428975704-1001\...\Run: [Amazon Music] => C:\Users\Mike\AppData\Local\Amazon Music\Amazon Music Helper.exe [6281536 2014-09-05] () HKU\S-1-5-21-1920574516-490169793-428975704-1001\...\Run: [Pinger] => C:\Program Files (x86)\Pinger\Pinger.exe [10581504 2013-08-23] () HKU\S-1-5-21-1920574516-490169793-428975704-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [28917376 2015-05-14] (Skype Technologies S.A.) HKU\S-1-5-21-1920574516-490169793-428975704-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2892992 2015-06-04] (Valve Corporation) HKU\S-1-5-21-1920574516-490169793-428975704-1001\...\MountPoints2: {b92e7b89-6c15-11e4-be85-3c970e7b8a03} - "H:\Windows\AutoRun.exe" {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B} HKU\S-1-5-21-1920574516-490169793-428975704-1001\...\MountPoints2: {ef0d53b6-9657-11e4-be8e-3c970e7b8a03} - "H:\VZW_Software_upgrade_assistant.exe" HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [BitTorrent] => C:\Users\Mike\AppData\Roaming\BitTorrent\BitTorrent.exe [1696104 2015-05-11] (BitTorrent Inc.) HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Amazon Music] => C:\Users\Mike\AppData\Local\Amazon Music\Amazon Music Helper.exe [6281536 2014-09-05] () HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Pinger] => C:\Program Files (x86)\Pinger\Pinger.exe [10581504 2013-08-23] () HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [28917376 2015-05-14] (Skype Technologies S.A.) HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2892992 2015-06-04] (Valve Corporation) HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {b92e7b89-6c15-11e4-be85-3c970e7b8a03} - "H:\Windows\AutoRun.exe" {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B} HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {ef0d53b6-9657-11e4-be8e-3c970e7b8a03} - "H:\VZW_Software_upgrade_assistant.exe" Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk [2014-10-06] ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-04-22] (Avast Software s.r.o.) ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) AutoConfigURL: [S-1-5-21-1920574516-490169793-428975704-1001] => C:\Users\Mike\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\BAC_PAC.js AutoConfigURL: [S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0] => C:\Users\Mike\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\BAC_PAC.js HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1920574516-490169793-428975704-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://easy-google-search.blogspot.com HKU\S-1-5-21-1920574516-490169793-428975704-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com HKU\S-1-5-21-1920574516-490169793-428975704-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://easy-google-search.blogspot.com HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-22] (Avast Software s.r.o.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-22] (Avast Software s.r.o.) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation) DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095} Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62 FireFox: ======== FF ProfilePath: C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\wlmivnt3.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-23] () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-23] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-25] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1920574516-490169793-428975704-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mike\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-09-27] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-1920574516-490169793-428975704-1001: electronicarts.com/GameFacePlugin -> C:\Users\Mike\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll [2012-12-20] (Electronic Arts) FF Plugin HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mike\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-09-27] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-1920574516-490169793-428975704-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: electronicarts.com/GameFacePlugin -> C:\Users\Mike\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll [2012-12-20] (Electronic Arts) FF Extension: Adblock Plus - C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\wlmivnt3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-25] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-09-25] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found] Chrome: ======= CHR Profile: C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-20] CHR Extension: (Google Docs) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-20] CHR Extension: (Google Drive) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-20] CHR Extension: (YouTube) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-20] CHR Extension: (Google Search) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-20] CHR Extension: (Google Sheets) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-20] CHR Extension: (AdBlock) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-10-17] CHR Extension: (Translator Context) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkdkohkdahffmjhcehilamblbpnjpmlo [2014-12-01] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-16] CHR Extension: (No Name) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2015-06-25] CHR Extension: (Google Wallet) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-20] CHR Extension: (Gmail) - C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-20] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-22] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-22] (Avast Software s.r.o.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3461072 2015-06-16] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [312816 2015-06-16] (AVG Technologies CZ, s.r.o.) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272776 2014-09-03] () S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-04-22] (Electronic Arts) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [38424 2010-10-18] (Google Inc) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-22] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-04-22] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-22] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-22] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-22] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-06-26] (Avast Software s.r.o.) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-04-22] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-04-22] () S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [287200 2015-05-19] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [256992 2015-04-15] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [224224 2015-05-12] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [285152 2015-05-12] (AVG Technologies CZ, s.r.o.) R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6822984 2013-03-07] (Broadcom Corporation) R3 DFX11_1; C:\Windows\system32\drivers\dfx11_1x64.sys [28008 2012-12-13] (Windows (R) Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-09-22] (Disc Soft Ltd) S3 ghsandroid; C:\Windows\System32\Drivers\ghsandroid.sys [38424 2011-03-30] (Google Inc) S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2015-06-26] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-16] (Synaptics Incorporated) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-09-25] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-26 14:19 - 2015-06-26 14:19 - 00027229 ____C C:\Users\Mike\Desktop\FRST.txt 2015-06-26 14:18 - 2015-06-26 14:19 - 00000000 ___DC C:\FRST 2015-06-26 14:16 - 2015-06-26 14:16 - 02112512 ____C (Farbar) C:\Users\Mike\Desktop\FRST64.exe 2015-06-26 13:39 - 2015-06-26 13:39 - 21546080 ____C (Malwarebytes Corporation ) C:\Users\Mike\Downloads\mbam-setup-2.1.6.1022.exe 2015-06-25 15:28 - 2015-06-25 15:33 - 00000000 ___DC C:\AdwCleaner 2015-06-25 15:27 - 2015-06-25 15:28 - 02244096 ____C C:\Users\Mike\Downloads\AdwCleaner.exe 2015-06-24 15:28 - 2015-06-24 15:32 - 00000000 ___DC C:\Users\Mike\Downloads\Dragonball_Z_Budokai_2_USA_PROPER_NGC-REACT0R 2015-06-24 05:57 - 2015-06-24 06:17 - 00056780 ____C C:\Users\Mike\Downloads\herostat.cfg 2015-06-24 05:45 - 2015-06-24 05:45 - 00000000 ___DC C:\Users\Mike\Downloads\MUA_Joker_v2.1_BLaw 2015-06-24 05:24 - 2015-06-24 05:24 - 01517917 ____C C:\Users\Mike\Downloads\MUA_X360_PC_Fix.zip 2015-06-24 05:24 - 2015-06-24 05:24 - 00000000 ___DC C:\Users\Mike\Downloads\MUA_X360_PC_Fix 2015-06-24 04:52 - 2015-06-24 04:52 - 00000000 ___DC C:\Users\Mike\AppData\Local\Logitech 2015-06-24 04:51 - 2015-06-24 04:51 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2015-06-24 04:51 - 2015-06-24 04:51 - 00000000 ___DC C:\Program Files\Logitech 2015-06-24 04:51 - 2015-06-24 04:51 - 00000000 ___DC C:\Program Files\Common Files\Logitech 2015-06-24 01:25 - 2015-06-24 01:25 - 00000000 ___DC C:\Users\Mike\Documents\Activision 2015-06-24 01:25 - 2015-06-24 01:25 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\Activision 2015-06-24 01:04 - 2015-06-24 01:04 - 00000000 ___DC C:\Users\Mike\Downloads\OfficialChars_1.3 2015-06-24 00:41 - 2015-06-24 00:41 - 00001086 ____C C:\WINDOWS\DXError.log 2015-06-24 00:41 - 2015-06-24 00:41 - 00000000 _SHDC C:\WINDOWS\ftpcache 2015-06-24 00:40 - 2015-06-24 00:40 - 00001970 ____C C:\Users\Public\Desktop\Marvel(TM) - Ultimate Alliance.lnk 2015-06-24 00:40 - 2015-06-24 00:40 - 00000296 ____C C:\WINDOWS\game.ini 2015-06-24 00:40 - 2015-06-24 00:40 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision 2015-06-24 00:00 - 2015-06-24 00:00 - 00000000 ___DC C:\Program Files (x86)\Activision 2015-06-23 21:55 - 2015-06-23 21:55 - 00769536 ____C C:\Users\Mike\Downloads\MicrosoftFixit50639.msi 2015-06-23 17:11 - 2015-06-23 17:12 - 17276616 ____C (Logitech ) C:\Users\Mike\Downloads\lgs510_x64.exe 2015-06-23 16:30 - 2015-06-23 16:30 - 00000000 ___DC C:\Users\Mike\AppData\Local\Fallout3 2015-06-23 16:29 - 2015-06-23 16:29 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace 2015-06-23 15:32 - 2015-06-23 15:32 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Softworks 2015-06-23 15:31 - 2015-06-23 15:32 - 00000000 ___DC C:\ProgramData\Fallout3 2015-06-23 15:31 - 2015-06-23 15:31 - 00000000 ___DC C:\Program Files (x86)\Bethesda Softworks 2015-06-23 14:18 - 2015-06-23 14:19 - 18363623 ____C C:\Users\Mike\Downloads\MUA_Joker_v2.1_BLaw.rar 2015-06-23 13:58 - 2015-06-23 13:58 - 74931415 ____C C:\Users\Mike\Downloads\OfficialChars_1.3.7z 2015-06-22 04:21 - 2015-06-22 04:22 - 57440724 ___RC C:\Users\Mike\Downloads\Aqua Teen Hunger Force S11E01 HDTV x264-W4F.mp4 2015-06-22 01:47 - 2015-06-22 01:47 - 24572646 ___RC C:\Users\Mike\Downloads\Boston [the bootleg].mp4 2015-06-18 21:02 - 2015-06-18 21:02 - 00001198 ____C C:\Users\Mike\Desktop\Pinball.lnk 2015-06-18 21:02 - 2015-06-18 21:02 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2015-06-18 21:02 - 2015-06-18 21:02 - 00000000 ___DC C:\Program Files (x86)\Microsoft Games 2015-06-17 09:04 - 2015-06-17 09:09 - 119655014 ____C C:\Users\Mike\Documents\15jb2208_jbv.avi 2015-06-17 09:04 - 2015-06-17 09:05 - 20992000 ____C C:\Users\Mike\Documents\14jb2108_jbv.avi 2015-06-16 20:44 - 2015-06-16 21:33 - 00008412 ____C C:\Users\Mike\Downloads\1646 - Dragon Ball Z - Buu's Fury (U)(Psychosis).clt 2015-06-16 14:10 - 2015-06-17 17:51 - 00008192 ____C C:\Users\Mike\Downloads\1646 - Dragon Ball Z - Buu's Fury (U)(Psychosis).sav 2015-06-16 13:56 - 1996-12-25 00:32 - 08388608 ____C C:\Users\Mike\Downloads\1646 - Dragon Ball Z - Buu's Fury (U)(Psychosis).gba 2015-06-16 13:25 - 2015-06-22 23:00 - 00000000 ___DC C:\Users\Mike\Downloads\Pokemon 2015-06-16 13:20 - 2015-06-16 13:33 - 00000000 ___DC C:\Users\Mike\Downloads\desmume 2015-06-12 09:14 - 2015-06-19 23:02 - 00792568 ____C (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-06-12 09:14 - 2015-06-19 23:02 - 00178168 ____C (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-06-12 08:31 - 2015-06-12 08:31 - 00000000 ___DC C:\Program Files\Common Files\AV 2015-06-11 10:15 - 2015-06-11 10:16 - 59349800 ___RC C:\Users\Mike\Downloads\Thor Annual 001 (2015) (Digital) (Zone-Empire).cbr 2015-06-10 05:52 - 2015-04-24 22:34 - 00653824 ____C (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2015-06-10 05:52 - 2015-04-24 22:33 - 00549888 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2015-06-10 05:51 - 2015-05-27 10:35 - 24917504 ____C (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-06-10 05:51 - 2015-05-27 10:08 - 19607040 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-06-10 05:51 - 2015-05-22 23:15 - 00503808 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-06-10 05:51 - 2015-05-22 23:14 - 00341504 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec 2015-06-10 05:51 - 2015-05-22 23:10 - 02278912 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-06-10 05:51 - 2015-05-22 23:05 - 00664064 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-06-10 05:51 - 2015-05-22 23:04 - 00620032 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2015-06-10 05:51 - 2015-05-22 22:47 - 04305920 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-06-10 05:51 - 2015-05-22 22:38 - 00689152 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-06-10 05:51 - 2015-05-22 22:37 - 02052608 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-06-10 05:51 - 2015-05-22 22:28 - 12829696 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-06-10 05:51 - 2015-05-22 22:20 - 01950720 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-06-10 05:51 - 2015-05-22 22:16 - 01309696 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-06-10 05:51 - 2015-05-22 22:14 - 00710144 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-06-10 05:51 - 2015-05-22 15:00 - 02885632 ____C (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-06-10 05:51 - 2015-05-22 15:00 - 00584192 ____C (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-06-10 05:51 - 2015-05-22 15:00 - 00417792 ____C (Microsoft Corporation) C:\WINDOWS\system32\html.iec 2015-06-10 05:51 - 2015-05-22 14:52 - 06026240 ____C (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-06-10 05:51 - 2015-05-22 14:47 - 00816640 ____C (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-06-10 05:51 - 2015-05-22 14:47 - 00814080 ____C (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2015-06-10 05:51 - 2015-05-22 14:06 - 00801280 ____C (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-06-10 05:51 - 2015-05-22 14:05 - 02125824 ____C (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2015-06-10 05:51 - 2015-05-22 13:57 - 14404096 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-06-10 05:51 - 2015-05-22 13:50 - 02426880 ____C (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-06-10 05:51 - 2015-05-22 13:49 - 02865152 ____C (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2015-06-10 05:51 - 2015-05-22 13:38 - 01545728 ____C (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-06-10 05:51 - 2015-05-22 13:26 - 00800768 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-06-10 05:50 - 2015-05-22 22:48 - 00076288 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2015-06-10 05:50 - 2015-05-22 22:47 - 00285696 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2015-06-10 05:50 - 2015-05-22 22:38 - 00327168 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-06-10 05:50 - 2015-05-22 22:28 - 01042944 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2015-06-10 05:50 - 2015-05-22 14:48 - 00633856 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll 2015-06-10 05:50 - 2015-05-22 14:24 - 00092160 ____C (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-06-10 05:50 - 2015-05-22 14:23 - 00145408 ____C (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2015-06-10 05:50 - 2015-05-22 14:21 - 00316928 ____C (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2015-06-10 05:50 - 2015-05-22 14:09 - 00262144 ____C (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2015-06-10 05:49 - 2015-05-22 22:47 - 00128000 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2015-06-10 05:49 - 2015-05-22 22:43 - 00880128 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-06-10 05:49 - 2015-05-22 14:15 - 01032704 ____C (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-06-10 05:49 - 2015-05-22 14:08 - 00374272 ____C (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2015-06-10 05:49 - 2015-05-21 12:47 - 04177920 ____C (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-06-09 04:03 - 2015-06-09 04:03 - 00513248 ____C C:\WINDOWS\Minidump\060915-43109-01.dmp 2015-06-07 01:16 - 2015-06-09 04:03 - 00000000 ___DC C:\WINDOWS\Minidump 2015-06-07 01:16 - 2015-06-07 01:16 - 00540848 ____C C:\WINDOWS\Minidump\060715-74046-01.dmp 2015-06-05 18:59 - 2015-06-05 18:59 - 00000221 ____C C:\Users\Mike\Desktop\FINAL FANTASY VII.url 2015-06-05 18:47 - 2015-06-05 18:47 - 00000000 ___DC C:\Users\Mike\AppData\Local\Steam 2015-06-05 18:44 - 2015-06-05 18:44 - 00000986 ____C C:\Users\Public\Desktop\Steam.lnk 2015-06-05 18:44 - 2015-06-05 18:44 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2015-06-05 18:36 - 2015-06-05 18:36 - 00000000 ___DC C:\Users\Mike\Desktop\Final Fantasy VII (Online Game Code) 2015-06-05 18:34 - 2015-06-05 18:34 - 01054064 ____C (Amazon Services LLC) C:\Users\Mike\Downloads\Final_Fantasy_VII_Online_Game_Code_Downloader.exe 2015-06-05 04:10 - 2015-06-14 11:16 - 00000000 ___DC C:\Users\Mike\Downloads\zsnesw151 2015-05-30 19:43 - 2015-05-30 19:43 - 00131072 ____C C:\Users\Mike\save 1.mcr 2015-05-30 19:31 - 2015-05-30 19:31 - 00134976 ____C C:\Users\Mike\Downloads\final_fantasy_vii_a.GME 2015-05-30 15:42 - 2015-06-05 19:18 - 00000000 ___DC C:\Users\Mike\Documents\Square Enix 2015-05-30 15:21 - 2015-05-30 15:21 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Black_Chocobo 2015-05-30 15:21 - 2015-05-30 15:21 - 00000000 ___DC C:\Program Files (x86)\Black_Chocobo 2015-05-30 13:27 - 1998-07-17 13:36 - 00140800 ____C (The Duck Corporation) C:\WINDOWS\SysWOW64\tm20dec.ax 2015-05-30 13:27 - 1997-12-17 18:33 - 00304128 ____C (InstallShield Software Corporation) C:\WINDOWS\IsUninst.exe 2015-05-30 07:27 - 2015-05-30 07:27 - 00001287 ____C C:\Users\Mike\Desktop\Final Fantasy IV.lnk 2015-05-30 07:27 - 2015-05-30 07:27 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\Final Fantasy IV 2015-05-30 07:27 - 2015-05-30 07:27 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics 2015-05-30 07:22 - 2015-05-30 07:22 - 00000000 ___DC C:\Program Files (x86)\R.G. Mechanics 2015-05-30 00:37 - 2015-05-30 21:07 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Final Fantasy VII 2015-05-29 22:39 - 2015-05-29 22:39 - 00000000 ___DC C:\Program Files (x86)\SystemRequirementsLab 2015-05-29 00:27 - 2015-06-14 12:12 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\CDisplayEx 2015-05-29 00:26 - 2015-05-29 00:26 - 00000859 ____C C:\Users\Mike\Desktop\CDisplayEx.lnk 2015-05-29 00:26 - 2015-05-29 00:26 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDisplayEx 2015-05-29 00:26 - 2015-05-29 00:26 - 00000000 ___DC C:\Program Files\CDisplayEx 2015-05-29 00:23 - 2015-05-29 00:24 - 68777289 ____C C:\Users\Mike\Downloads\Deadpool's Secret Secret Wars 001 (2015) (4 covers) (Digital) (Mephisto-Empire).cbr 2015-05-29 00:22 - 2015-05-29 00:23 - 180735120 ____C C:\Users\Mike\Downloads\Deadpool 045 (2015) (5 covers) (Digital-Empire).cbr 2015-05-28 07:15 - 2015-06-01 23:18 - 00015142 ____C C:\Users\Mike\Documents\nwl top 100.odt 2015-05-28 05:43 - 2015-05-31 23:58 - 00026039 ____C C:\Users\Mike\Downloads\Byakko.odt 2015-05-27 05:33 - 2015-05-27 05:33 - 00001260 ____C C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Free File Shredder.lnk 2015-05-27 05:33 - 2015-05-27 05:33 - 00001236 ____C C:\Users\Mike\Desktop\Free File Shredder.lnk 2015-05-27 05:33 - 2015-05-27 05:33 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\New Version Available 2015-05-27 05:33 - 2015-05-27 05:33 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\Free File Shredder 2015-05-27 05:33 - 2015-05-27 05:33 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free File Shredder 2015-05-27 05:33 - 2015-05-27 05:33 - 00000000 ___DC C:\Program Files (x86)\Free File Shredder ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-26 14:17 - 2014-11-06 16:22 - 14561792 __SHC C:\Users\Mike\Downloads\Thumbs.db 2015-06-26 14:09 - 2014-09-20 21:47 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\vlc 2015-06-26 14:00 - 2013-08-22 11:36 - 00000000 ___DC C:\WINDOWS\system32\sru 2015-06-26 13:52 - 2015-01-25 16:09 - 00000830 ____C C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-06-26 13:46 - 2014-09-20 15:00 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1920574516-490169793-428975704-1001 2015-06-26 13:41 - 2015-01-25 22:21 - 00136408 ____C (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-06-26 13:40 - 2015-01-25 22:21 - 00001125 ____C C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-06-26 13:40 - 2015-01-25 22:21 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-06-26 13:40 - 2015-01-25 22:21 - 00000000 ___DC C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-06-26 13:36 - 2014-09-20 16:07 - 00000914 ____C C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-06-26 12:10 - 2014-09-25 13:56 - 00442264 ____C (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswsp.sys 2015-06-26 11:43 - 2014-09-25 13:58 - 00000000 ___DC C:\ProgramData\MFAData 2015-06-26 11:36 - 2014-09-20 16:07 - 00000910 ____C C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-06-26 09:56 - 2014-09-24 22:10 - 01636354 ____C C:\WINDOWS\WindowsUpdate.log 2015-06-26 07:49 - 2014-09-25 19:00 - 00003902 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{90E7C39F-DD58-43F3-89D7-35F47CA4AB41} 2015-06-26 03:47 - 2015-05-19 17:47 - 00485469 ____C C:\WINDOWS\setupact.log 2015-06-25 16:52 - 2012-07-26 03:59 - 00000000 ___DC C:\WINDOWS\CbsTemp 2015-06-25 15:41 - 2014-10-01 13:41 - 00000000 ___DC C:\Program Files (x86)\Steam 2015-06-25 15:39 - 2014-09-24 22:26 - 00000000 __DOC C:\Users\Mike\OneDrive 2015-06-25 15:36 - 2013-08-22 10:45 - 00000006 ___HC C:\WINDOWS\Tasks\SA.DAT 2015-06-25 15:34 - 2013-08-22 09:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2015-06-25 15:32 - 2013-03-07 18:26 - 00000000 ___DC C:\Program Files (x86)\Amazon 2015-06-25 06:00 - 2013-08-22 11:36 - 00000000 ___DC C:\WINDOWS\AppReadiness 2015-06-24 06:03 - 2014-12-23 18:09 - 00003886 ____C C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2015-06-24 00:41 - 2014-10-11 22:25 - 00184392 ____C C:\WINDOWS\DirectX.log 2015-06-24 00:41 - 2013-03-07 17:57 - 00000000 __HDC C:\Program Files (x86)\InstallShield Installation Information 2015-06-24 00:02 - 2014-09-20 22:11 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\BitTorrent 2015-06-23 23:54 - 2014-09-20 14:53 - 00000000 ___DC C:\Users\Mike\AppData\Local\VirtualStore 2015-06-23 22:37 - 2015-03-26 04:44 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\Skype 2015-06-23 22:05 - 2014-03-18 05:54 - 00044022 ____C C:\WINDOWS\PFRO.log 2015-06-23 16:30 - 2014-11-28 10:13 - 00000000 ___DC C:\Users\Mike\Documents\My Games 2015-06-23 16:29 - 2014-10-25 11:14 - 00000000 ___DC C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2015-06-23 14:52 - 2014-09-24 21:53 - 00000000 ___DC C:\Users\Mike 2015-06-23 12:52 - 2015-01-25 16:09 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-06-23 08:08 - 2014-09-25 14:02 - 00000992 ____C C:\Users\Public\Desktop\AVG 2015.lnk 2015-06-23 08:08 - 2014-09-25 14:02 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2015-06-22 16:39 - 2014-09-20 17:00 - 00002214 ____C C:\Users\Public\Desktop\Google Chrome.lnk 2015-06-19 23:19 - 2013-08-22 09:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2015-06-18 00:12 - 2014-09-25 13:56 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update 2015-06-14 19:22 - 2014-03-18 06:03 - 00863592 ____C C:\WINDOWS\system32\PerfStringBackup.INI 2015-06-12 09:37 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\rescache 2015-06-12 09:13 - 2013-08-22 10:44 - 00362888 ____C C:\WINDOWS\system32\FNTCACHE.DAT 2015-06-12 09:08 - 2013-08-22 11:36 - 00000000 ___DC C:\WINDOWS\PolicyDefinitions 2015-06-10 08:25 - 2014-09-21 13:20 - 00000000 ___DC C:\WINDOWS\system32\MRT 2015-06-10 08:17 - 2014-09-21 13:20 - 140135120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-06-09 02:09 - 2015-03-11 07:52 - 00028377 ____C C:\Users\Mike\Documents\Markas 2.odt 2015-06-07 16:11 - 2015-01-01 04:55 - 00001127 ____C C:\Users\Mike\Desktop\Pinger.lnk 2015-06-05 19:47 - 2015-03-26 04:43 - 00000000 ___DC C:\ProgramData\Skype 2015-06-05 18:59 - 2014-10-01 14:08 - 00000000 ___DC C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-06-01 01:23 - 2015-05-24 04:21 - 00921624 ____C C:\img2-001.raw 2015-05-30 07:27 - 2014-10-11 22:04 - 00000000 ___DC C:\ProgramData\Package Cache 2015-05-27 16:01 - 2015-03-26 04:43 - 00000000 __RDC C:\Program Files (x86)\Skype ==================== Files in the root of some directories ======= 2014-12-17 08:23 - 2014-12-17 08:23 - 0001479 ____C () C:\Users\Mike\AppData\Local\recently-used.xbel 2013-03-07 18:02 - 2013-03-07 18:02 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2014-12-11 15:09 - 2014-12-11 15:09 - 0012719 ____C () C:\ProgramData\ucxrypwh.kkh Some files in TEMP: ==================== C:\Users\Mike\AppData\Local\Temp\h0jpclbj.dll C:\Users\Mike\AppData\Local\Temp\Quarantine.exe C:\Users\Mike\AppData\Local\Temp\sqlite3.dll C:\Users\Mike\AppData\Local\Temp\UNINSTALLER-6180.exe C:\Users\Mike\AppData\Local\Temp\Uninstaller-8296.exe C:\Users\Mike\AppData\Local\Temp\Uninstaller-8964.exe C:\Users\Mike\AppData\Local\Temp\Uninstaller-9260.exe C:\Users\Mike\AppData\Local\Temp\Uninstaller-9308.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-19 20:33 ==================== End of log ============================